---
id: CVE-2020-12357
title: >-
  Improper initialization in the firmware for some Intel(R) Processors may allow
  a privileged user to potentially enable escalation of privilege via local
  access.
summary: >-
  Improper initialization in the firmware for some Intel(R) Processors may allow
  a privileged user to potentially enable escalation of privilege via local
  access.
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-665
vendor: netapp
product: cloud_backup
affected:
  - bios
  - cloud_backup
  - aff_bios
  - e-series_bios
  - fas_bios
  - hci_compute_node_bios
  - hci_storage_node_bios
  - solidfire_bios
  - simatic_field_pg_m6_firmware
  - simatic_ipc427e_firmware
  - simatic_ipc477e_firmware
  - simatic_ipc477e_pro_firmware
  - simatic_ipc547g_firmware
  - simatic_ipc627e_firmware
  - simatic_ipc647e_firmware
  - simatic_ipc677e_firmware
  - simatic_ipc847e_firmware
  - simatic_itp1000_firmware
  - simatic_cpu_1518-4_firmware
published: '2021-06-09'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:21.927'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-12357'
references:
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdf'
    label: secure@intel.com
  - url: 'https://security.netapp.com/advisory/ntap-20210702-0002/'
    label: secure@intel.com
  - url: >-
      https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00463.html
    label: secure@intel.com
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210702-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00463.html
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00346
epssPercentile: 0.26014
ingestedAt: '2026-10-08T22:11:53.733Z'
---

## Overview

Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

## Affected

- `bios`
- `cloud_backup`
- `aff_bios`
- `e-series_bios`
- `fas_bios`
- `hci_compute_node_bios`
- `hci_storage_node_bios`
- `solidfire_bios`
- `simatic_field_pg_m6_firmware`
- `simatic_ipc427e_firmware`
- `simatic_ipc477e_firmware`
- `simatic_ipc477e_pro_firmware`
- `simatic_ipc547g_firmware`
- `simatic_ipc627e_firmware`
- `simatic_ipc647e_firmware`
- `simatic_ipc677e_firmware`
- `simatic_ipc847e_firmware`
- `simatic_itp1000_firmware`
- `simatic_cpu_1518-4_firmware`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
